All Apps and Add-ons

O365 message tracking logs

tylers
New Member

The Security Essentials documentation (https://docs.splunksecurityessentials.com/data-onboarding-guides/office-365/) states that "The Office365 Reporting Add-on lets you collect Exchange message-tracking logs by querying the Office 365 Reporting web service API and indexing the results.".

Based on my testing and the comments made here in Splunk Answers related to the add-on, it is no longer supported and no longer works to support pulling down message trace logs. Is there a newer recommended way for pulling down these logs?

0 Karma

marcluescher
Explorer

We are in the same boat, O365 no longer supports basic authentication for O365 to get those log files.

Having looked at some possible solutions we might write our own TA to get this again working. An alternate solution is to sue a powershell script to dump the log files hourly to a share and import from there.

Happy to share more when interested.

 

-Marc

 

Tags (1)
0 Karma

mhotsi
Explorer

Hello Marc, I would like to know more about the powerscript solution.

0 Karma

adalbor
Builder

Would love to  hear more about your proposed solution @marcluescher 

We have thought about taking the powershell route too but havent spent much time on it to be honest.

J_lo
Engager

Hi @marcluescher 


Any luck going down the Powershell route? 


Thanks in advance.

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...